Skip to main content
A software developer is thinking on improving the efficiency of the AI system.

Nacha 2026 Rule Changes: Fraud Monitoring Requirements

2026 Nacha rules require ACH participants to implement risk-based fraud monitoring.

For organizations that originate, receive, or process Automated Clearing House (ACH) transactions, the 2026 Nacha updates make fraud monitoring a core part of operational readiness. As part of its broader risk management initiative, Nacha has introduced new fraud monitoring requirements that significantly expand expectations for participants in the ACH network. These updates are designed to reduce fraud risk and improve detection and recovery of fraudulent transactions.1

Two-Phase Implementation Timeline

  • Phase 1 – Effective March 20, 20262
    • Applies to:
      • All ODFIs
      • High-volume Originators, Third-Party Senders (TPSs), and Third-Party Service Providers (TPSPs) (≥ 6 million ACH originations in 2023)
      • Receiving Depository Financial Institutions (RDFIs) with ≥ 10 million ACH receipts
  • Phase 2 – Effective June 19, 20263
    • Expands requirements to all remaining ACH participants, regardless of size or volume

Shift to Mandatory Risk-Based Fraud Monitoring

One of the most significant aspects of the 2026 Nacha updates is the transition to mandatory, risk-based fraud monitoring across the ACH network. Under the new framework, all covered entities are required to establish and implement formal processes and procedures designed to identify potentially fraudulent ACH activity. These processes must not only exist but also be reasonably designed to detect suspicious or unauthorized transactions.

This represents a notable departure from prior requirements. Historically, fraud monitoring expectations were limited in scope—primarily focused on specific transaction types such as WEB debits and micro-entries. In contrast, the updated rules expand monitoring expectations to all ACH entry types, signaling a broader, networkwide emphasis on proactive fraud detection.

Closely tied to this shift is an increased emphasis on flexibility and documentation. The rules replace the long-standing concept of a “commercially reasonable detection system” with a requirement for risk-based processes and procedures tailored to an organization’s specific role, transaction volume, and risk profile. In practice, this means organizations must move beyond one-size-fits-all controls and instead develop monitoring approaches that are responsive to their unique operational risks.

Effective monitoring programs will typically include the ability to identify anomalies in transaction activity—such as unexpected spikes, changes in payment patterns, or unusual account behavior—while also establishing a baseline of “normal” activity to better detect deviations.

Forvis Mazars’ Perspective: Audit & Risk Implications

From an audit and compliance perspective, these changes represent a clear shift in expectations—from simply having controls in place to demonstrating that those controls are appropriately designed, consistently executed, and well-documented.

Organizations should anticipate increased scrutiny over both the design and operating effectiveness of their fraud monitoring programs. This includes demonstrating that monitoring logic is aligned with known fraud risks—such as business email compromise or vendor impersonation—and that alert thresholds are calibrated in a way that is meaningful and actionable, rather than overly generic.

Another key implication is the growing importance of formalization and documentation. The repeated emphasis on “processes and procedures” signals that informal or ad hoc monitoring approaches will no longer be sufficient. Instead, organizations are expected to maintain clearly documented frameworks, defined roles and responsibilities, and supporting evidence of monitoring activities and oversight. From an audit standpoint, this typically includes written policies, monitoring logs, exception reporting, and documentation of how alerts are investigated and resolved.

The rule changes also significantly expand the scope of responsibility—particularly for originators and TPSPs. Many organizations have historically relied on their banking partners to perform most fraud detection activities. However, the new requirements shift a greater portion of responsibility directly to originators and third-party participants, who must now demonstrate that they have their own monitoring capabilities in place, even when leveraging third-party tools or platforms.

Finally, the move to a risk-based framework underscores the need for ongoing review and adaptability. Fraud risks and transaction patterns evolve over time, and monitoring processes should evolve accordingly. Organizations should be prepared to periodically reassess their controls, incorporating emerging fraud trends and changes in transaction activity. From an audit perspective, this will likely translate into expectations for regular reviews of monitoring programs and documented updates to thresholds, rules, or procedures as needed.

How Organizations Can Prepare

Organizations should begin evaluating their fraud monitoring frameworks now to prepare for the 2026 Nacha rule changes. This includes reviewing policies and procedures, confirming monitoring activities are aligned to relevant fraud risks, and ensuring documentation is sufficient to support consistent execution. Taking these steps can help strengthen the control environment, improve operational readiness, and position the organization for compliance with the new requirements.

Policy & Procedures

Policy Updates

  • Existing ACH or fraud monitoring policies should clearly describe how often monitoring is performed, what controls or tools are used, and what types of activity are reviewed for potential fraud indicators.
  • Examples of monitoring activities such as evaluation of transaction volume, SEC code usage, new payee activity, and deviations from historical originator behavior can be included in the policy. In addition, a process of identification of fraudulent activity, escalation, and reporting to all parties should be included within the policy.

Roles & Responsibilities

  • The policy should clearly define the roles and responsibilities of individuals or departments responsible for daily fraud monitoring, alert review, escalation, investigation, and internal or external reporting, including reporting to Nacha when required.

Fraud Monitoring Controls

Originator Monitoring

Organizations should design originator monitoring to identify activity that falls outside expected patterns. This may include sudden increases in transaction volume, changes in SEC code usage, or new payees and account numbers that have not previously been used. Monitoring should be tailored to the organization’s ACH activity and focused on scenarios most likely to indicate fraud.

Transaction activity should also be evaluated against historical behavior to identify unusual trends or anomalies. This can include unexpected use of higher-risk SEC codes, repeated unauthorized returns, or other changes that may suggest elevated fraud risk or a need to reassess monitoring thresholds.

Receiver Monitoring

Receiver-side monitoring should focus on identifying unusual or inconsistent transaction activity at the account level. This may include SEC code mismatches, such as a corporate transaction posting to a consumer account, as well as high-dollar transactions that are inconsistent with the account’s typical activity.

Monitoring should also consider transaction velocity and other account-level anomalies, including multiple deposits within a short period or activity involving new, dormant, or otherwise higher-risk accounts. These reviews can help organizations detect suspicious patterns earlier and determine whether additional investigation is warranted.

How Forvis Mazars Can Help

As organizations prepare for the 2026 Nacha fraud monitoring requirements, many are evaluating whether their governance, monitoring practices, documentation, and control frameworks are positioned to meet evolving expectations. Forvis Mazars can assist with fraud monitoring readiness assessments, policy and procedure development, control validation, documentation reviews, and audit readiness efforts designed to support a practical, risk-based approach to compliance.

For a deeper look at key considerations including governance, fraud risk assessments, monitoring controls, exception management, documentation retention, and audit readiness, download our complimentary Nacha Fraud Monitoring Readiness guide. The resource provides a practical checklist and framework to help organizations strengthen fraud monitoring programs and prepare for the upcoming rule changes.

Download Now

If you have any questions or need assistance, please reach out to a professional at Forvis Mazars.

  • 1“Nacha Operating Rules - New Rules,” nacha.org/newrules, February 6, 2026.
  • 2“Nacha Operating Rules – Risk Management Topics – (Fraud Monitoring Phase 1),” nacha.org, March 20, 2026.
  • 3“Nacha Operating Rules – Risk Management Topics – (Fraud Monitoring Phase 2),” nacha.org, June 19, 2026.

Related FORsights

Like what you see?
Subscribe to receive tailored insights directly to your inbox.